CVE-2011-0480
EPSS 1.3%
Description
Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.
How to fix CVE-2011-0480
To remediate CVE-2011-0480, upgrade the affected package to a fixed version below.
- Debian/ffmpeg—upgrade to 7:2.4.1-1 or later
Is CVE-2011-0480 being exploited?
Low — EPSS is 1.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 7:2.4.1-1